mcpbeat Sign in

Have I Been Pwned MCP Server

answering

Have I Been Pwned is answering right now. Last checked 14 min ago. It exposes 17 tools.

Breach intelligence API: email search, domain monitoring, passwords and stealer logs.

Uptime history 48 days of history · worst day 90%
48 days agonow
95.6%
Uptime 24h
87 of 91 checks
17
Tools
read from the server
97 ms
Response time
average over 24h
open, no key
Access
streamable-http

What changed 25

Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 27 August 2026. No other catalogue keeps this.

1 Sep a tool description was rewritten hibp_generate_domain_verification_dns_token
27 Aug 17 tools changed the parameters they ask for hibp_generate_domain_verification_dns_token, hibp_get_breach, hibp_get_breached_account and 14 more
27 Aug 7 tool descriptions were rewritten hibp_get_breached_account, hibp_get_breached_account_range, hibp_get_paste_account and 4 more

Have I Been Pwned does not always answer

Over the last week it answered 96.9% of our checks. We check every 15 minutes, so you hear about the next outage within the hour — not from your users.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 14 min ago.

run in your terminal
claude mcp add hibp --transport http https://haveibeenpwned.com/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "hibp": {
      "url": "https://haveibeenpwned.com/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.hibp]
url = "https://haveibeenpwned.com/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "hibp": {
      "url": "https://haveibeenpwned.com/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "hibp": {
      "url": "https://haveibeenpwned.com/mcp"
    }
  }
}

Available tools 17

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

hibp
hibp_generate_domain_verification_dns_token
Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request. Requires an authenticated subscription with domain-verification access.
hibp_get_breach
Look up a single public HIBP breach by its canonical breach name, such as Adobe.
hibp_get_breached_account
Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification filters to refine the result.
hibp_get_breached_account_range
Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anonymity access; compare each returned suffix with the remaining hash characters locally because a prefix alone cannot identify an account.
hibp_get_breached_domain
Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token.
hibp_get_latest_breach
Return the most recently added public breach currently loaded into HIBP.
hibp_get_paste_account
Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from breached-account lookup.
hibp_get_pwned_passwords_range
Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts.
hibp_get_stealer_logs_by_email
Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
hibp_get_stealer_logs_by_email_domain
Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
hibp_get_stealer_logs_by_website_domain
Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
hibp_get_subscription_status
Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use it to confirm access before feature-dependent lookups.
hibp_list_breaches
List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status.
hibp_list_data_classes
List the data classes used across public HIBP breach models, such as email addresses or passwords.
hibp_list_subscribed_domains
List the domains associated with the authenticated HIBP subscription.
hibp_send_domain_verification_email
Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access.
hibp_verify_domain_verification_dns_token
Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification access.

Endpoints

URLTransportStateLatencyChecked
https://haveibeenpwned.com/mcp streamable-http answering 36 ms 14 min ago

Alternatives to Have I Been Pwned

same job, measured the same way
Agentic News
by agentic-news

AI-powered news intelligence — 21 tools for personalized monitoring, briefings, and semantic search

answering
Hotel Rate Monitoring API
by veyvey45-eng

Remote MCP server for hotel rate monitoring, parity checks, and pricing intelligence via Apify.

answering
W
Agent Health
by autonet

Free owned-agent uptime monitoring, DNS domain proof, signed alerts and opt-in endpoint checks.

21 tools answering
Compete Competitive Intelligence
by niyonzimabryan

Typed access to monitored competitive changes, evidence, dossiers, research, and collection health.

58 installs/wk local only
Content Intelligence API
by ruvendors5-ops

9 MCP tools: extract, analyze, research, compare, monitor, brief. Pay-per-call x402 or subscribe.

9 tools answering
Changeflow
by stevebutterworth

AI-powered web monitoring. Track any website, get structured change intelligence.

30 installs/wk local only
Timps
by sandeeprdy1729

Persistent memory with contradiction detection, burnout monitoring, and 69 intelligence tools.

42 installs/wk local only
PeppolStatus
by peppolstatus

Peppol market intelligence and network monitoring: migrations, provider churn, leads, and uptime.

61 tools answering

Have I Been Pwned — questions

Answers built from our own checks of this server.

What can Have I Been Pwned do?
It exposes 17 tools, read directly from the server on our last check. Among them: hibp_generate_domain_verification_dns_token, hibp_get_breach, hibp_get_breached_account, hibp_get_breached_account_range, hibp_get_breached_domain, hibp_get_latest_breach and 11 more. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Have I Been Pwned working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 87 of 91 checks got a reply (95.6%), average response time 97 ms. The bar chart above shows every period we have measured.
How do I connect Have I Been Pwned?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Have I Been Pwned need an API key?
No. Have I Been Pwned completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 17 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Have I Been Pwned?
It answers our handshake in 97 ms on average, which is faster than 83% of all working MCP servers we measure. That puts it in the quick quarter of the ecosystem. The comparison comes from our own checks across the whole registry, every 15 minutes.